CVE-2023-52338

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jan 23, 2024
Updated: Jul 3, 2024
CWE ID 59

Summary

CVE-2023-52338 is a newly disclosed privilege escalation vulnerability affecting Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent. The issue arises from a link following vulnerability, enabling local attackers to escalate their privileges on targeted installations. It is important to note that an attacker must initially gain the capability to execute low-privileged code on the victim's system to successfully exploit this vulnerability. By exploiting this weakness, attackers could elevate their access, potentially leading to unauthorized system modifications or data exfiltration. System administrators are advised to apply the available patches promptly to mitigate the risk of potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Trend Micro Deep Security Agent
  • Trend Micro Deep Security

Affected Vendors

  • Trend Micro, Inc.